Privacy at PlushList
Your collection is personal. We treat it that way.
PlushList uses collection and extension data only to provide the organizer you asked for. It does not sell personal data or use it for advertising, credit decisions, or unrelated profiling.
Who operates PlushList
PlushList is an independent collector project operated by the owner of this deployment. For privacy, access, or deletion help, email chasetappan@gmail.com or visit the PlushList support page. You can also send a request through the Chrome Web Store listing's Support section.
Information the site stores
Supabase stores the account identifier, email address, and profile name provided by Google for sign-in. PlushList stores the collection details you choose to add: item titles and types, personal names, notes, ages, dates, purchase details, quantities, favorites, tags, wardrobe categories, the bear–wardrobe outfit relationships you choose, source links, and product image URLs. Records are scoped to your authenticated account.
What the Chrome helper stores and sends
After you affirmatively accept its in-extension data-use disclosure, the helper runs on buildabear.com and reads public product names, descriptions, SKUs, listed prices, canonical URLs, retailer-published image URLs, inferred item types, and wardrobe categories. It uses those fields to identify supported listings, place save controls, and prepare the item you choose. It sends one product's details over HTTPS only after you press a PlushList save control and choose Collection or Wish list. Unsaved public-listing details are not transmitted to PlushList or written to Chrome storage.
When you explicitly press Import my purchaseson a signed-in Build-A-Bear Order History page, the helper follows that account's order-history and order-detail pages in memory. It reads the displayed order status locally to exclude canceled, refunded, returned, and failed orders. It extracts only importable product names, SKUs, product URLs, retailer-published image URLs, inferred item types and wardrobe categories, quantities, displayed item prices, and purchase dates. It sends those normalized fields over HTTPS so PlushList can add new owned items, recognize items already saved, and move matching wish-list items into the collection. Gift cards and canceled, refunded, returned, or failed orders are skipped.
Shipping and billing addresses, payment details, tracking numbers, order totals, authentication cookies, and raw order pages are not sent to PlushList. Order numbers are used only within Build-A-Bear detail links and are never included in import records or sent to PlushList. Raw page responses are discarded from memory when the scan finishes. The helper does not inspect checkout pages, build or retain a general browsing history, or read unrelated page data. The selected product page URL is stored with the item so PlushList can link back to its source and avoid duplicate imports. After consent, opening the extension popup briefly checks the current tab's URL to report whether that page is supported; that check is not retained.
Chrome Sync stores the PlushList site origin and current consent version so those preferences can follow you between signed-in Chrome installations. Chrome local storage keeps the required connection token and the title, destination, and time of the most recent successful individual save. For an order-history import it keeps only the completion time and summary counts, not the imported product list or order contents. Local extension secrets are restricted to trusted extension contexts and are not placed in Sync. Chrome session storage temporarily keeps the time when PlushList last opened a sign-in tab so it can avoid opening duplicate tabs.
During setup, the extension sends the configured site URL and connection token to that PlushList site for verification. It may display the account name or email returned by the verification response so you can confirm which account is connected; it does not retain that response as extension settings.
Connection tokens
PlushList shows a new token once. On the server, it stores the token's SHA-256 hash for verification and a shortened, non-secret prefix so you can recognize the current connection; it does not store the complete token. Any browser holding that bearer token can add listing snapshots and order-history imports to your account, so keep it secret. Tokens become unusable after 90 days and can be replaced or revoked sooner from the Chrome helper page.
Product images and third parties
PlushList stores the public image URL published on a Build-A-Bear listing; it does not copy or upload the retailer's file. When the collection displays a remote image, the image host can receive ordinary request data such as your IP address, browser metadata, and request time. Product images and trademarks remain the property of their respective owners.
Google provides account authentication, Supabase manages the resulting account session and application data storage, Vercel provides application hosting, Chrome provides local and sync extension storage, and Build-A-Bear hosts linked product images. Those providers may process technical request or security logs under their own policies. PlushList does not disclose collection data to advertisers or data brokers.
Retention and control
Collection records and bear–wardrobe outfit relationships remain until you delete the related item or erase the PlushList account. A connection-token row, including its hash and shortened prefix, remains until revocation, replacement, or account deletion. Reaching the 90-day expiry makes the token unusable but does not by itself delete that row. Infrastructure providers may retain limited operational or security logs according to their own retention rules.
You can edit or delete individual items, revoke extension access, and clear the extension's Chrome storage by removing the extension. The control below permanently deletes this PlushList account, including its collection items, outfit relationships, tags, extension connection, and Supabase sign-in identity. It does not delete or otherwise change your Google Account.
Chrome Web Store Limited Use
PlushList's use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Data received from Chrome is used only to provide or secure PlushList's single-purpose save, import, and organize feature. It is not sold, used for personalized advertising, used to determine creditworthiness, or transferred for unrelated purposes. Human access is limited to what is necessary for security, legal compliance, or support you specifically request.
Children
PlushList is not directed to children under 13 and should not be used by anyone under 13. Do not enter a child's personal information in notes or collection fields. If you believe a child has provided personal information, use the support page to request its deletion.
Last updated August 14, 2026.